Skip to main content
Design Partner Programme · No fee

Thirty days. No fee. One honest answer.

A free design-partner engagement, not a paid trial. Connect your identity provider in about fifteen minutes. See the AI your organisation is actually running on day one. Leave with systems mapped to the frameworks that reach you, a working release gate, and a record you can hand to an auditor.

  • Free · design-partner track
  • Read-only to start
  • No endpoint agent
  • Bounded to 30 days
  • Out-of-scope list published
The thirty days· read-only to start
Thirty days · no fee
  • Day 1 · Connect + inventory
    read-only · about fifteen minutes
  • Map
    systems → the frameworks that reach you
  • Gate
    live in your pipeline, override logged
  • Day 30 · Record
    yours either way · no obligation

Before you start

Two questions you cannot answer yet

They arrive from the board, the regulator, or an enterprise customer’s security questionnaire. Usually all three, within the same quarter.

Question 01

“What AI are we running, and what is it touching?”

The honest answer in most organisations is a spreadsheet that was accurate once. Procurement knows the tools it bought. Nobody owns the AI features switched on inside tools you already licensed, or the agent a team stood up on a corporate card.

Question 02

“If we were asked tomorrow, could we prove it was governed?”

An inventory is not evidence. Evidence is a record showing what was found, who owned it, which control it was assessed against, what was decided, who overrode it, and that none of that was edited afterwards.

Day 1

Fifteen minutes to your first real inventory

Discovery runs off the identity provider you already own. That is the whole integration for week one.

Connect · about fifteen minutes
Day one, in order
  • Min 2 · App registration
    Microsoft Entra ID or Okta read-only scopes only
  • Min 7 · Consent
    we read sign-in activity and OAuth grants; we do not write to your directory
  • Min 15 · Inventory lands
    the usual blocker is calendar time with whoever owns the tenant
Not needed
  • Endpoint agent
  • MDM push
  • Network change
  • Proxy re-route
  • Data-warehouse build
  • Platform-team project

Nothing installed on a laptop. Nothing pushed through your MDM. Nothing built before you see something useful.

Discovery · via your identity provider· example data
IdP
6
Found
4
No owner yet
0
Agents installed

Scope

What is in. What is deliberately out.

Both lists get the same space on this page, because the second one is what tells you whether the first one is true.

In scope · three things, in order

01

Shadow-AI discovery

The day-one inventory.

Which AI tools and agents your people are actually signing into
Which third-party apps hold an OAuth grant against your tenant, and which of those nobody approved
The artefact most pilots end at. For us it is the input to everything else
02

Policy-to-control mapping

Against the frameworks that actually reach you.

UAE PDPL, NESA/SIA, ADHICS and DIFC/ADGM first; SAMA where KSA applies; EU AI Act, ISO/IEC 42001 and NIST AI RMF as the reference structure
Each discovered system gets an owner, a risk finding and a mapped control reference, so a technical finding and a compliance gap become one record instead of two
03

Promotion-gate enforcement

A hard gate at the release point.

Blocks promotion on evidenced risk, wired into your existing pipeline
A named human can override it (that is deliberate), and the override is logged with the name attached rather than quietly swallowed

Out of scope · stated up front

Deep and legacy telemetry connectors

Scoped separately

Splunk and comparable legacy integrations are real work. Pretending they fit inside 30 days would set the pilot up to fail.

Direct-to-runtime policy push

Roadmap · not shipped

Enforcement emits a decision into your pipeline. It does not reach into your production runtime and change configuration on its own.

No autonomous kill switch

Your controls enforce

We decide and evidence; we do not stop your AI systems. A vendor promising to autonomously kill production AI for you is describing a change-management problem, not a feature.

Not a scanner of everything

Not sold as shipped

Adversarial and red-team probing, membership-inference, model-inversion, extraction and training-data poisoning checks are not in the pilot. Some are roadmap.

Coverage is what routes through us

Gateway-routed only

Continuous where AI traffic is routed through the gateway: enforcement is inline there and the audit trail is tamper-evident. Scanning across the rest of your estate is on-demand rather than always-on.

We sit on top of the tools you already run rather than replacing them. That boundary holds for the whole thirty days.

Day 30

Four artefacts. Yours either way.

If you do not continue with us, you still keep what the pilot produced. That is the point of bounding it.

Hand-over · day 30· nothing converts
Day 30 · yours either way
  • A defensible shadow-AI inventory
    Not a survey response. Built from your own identity and consent records, with owners attached.
  • Systems mapped to frameworks, gaps visible
    Every discovered system against the regimes that reach you, including the ones where the honest answer is "no control mapped yet".
  • A working release gate
    Live in your pipeline, blocking on evidenced risk, with a logged human override path your engineers will actually accept.
  • A tamper-evident record
    Discovery, risk, decision, override: hash-chained, so an auditor can verify after the fact that the record was not edited.
Evidence ledger · hash-chained· example data
01 · Discovera91f…37c2
02 · Posture4d0b…ae19
03 · Gate77e5…10f4
04 · Provec3a8…9b6d
Signed head · Ed25519
An auditor verifies the chain after the fact. No trust in us required
Read against
EU AI Act
Mapped
ISO/IEC 42001
In Review
NIST AI RMF
Mapped
UAE PDPL
Mapped

Low risk

Low risk, and specifically why

“Low risk” is a claim every vendor makes. Here is the version you can check against the scope: six checks, drawn on what we actually touch.

Footprint · what we touch
What the pilot touches
  • Identity · read-only to start
    nothing we do in week one changes your environment
  • Endpoints · no new agent
    so no rollout and no rollback
  • Network · untouched
    no proxy re-route, no change
  • Budget · no fee, no purchase order
    no budget line to defend before you can start
What you get out of it
  • Bounded scope
    written down before we begin, out-of-scope list attached
  • Value on day one
    the inventory lands before the gate work starts
  • Candor about limits before you sign, not after
    this page is the evidence of that

Design Partner Programme

The pilot is free. Here is the whole of it.

The AI Governance Command Center is pre-GA, and we would rather build it against four regulated environments than a hundred opinions. That is the entire reason this costs nothing, and it is the whole arrangement, not the summary of a longer contract.

DAY 0No fee, no purchase orderThe thirty days cost nothing. No trial licence to sign, no invoice at the end, and no budget line to defend before you can find out what your organisation is running.
DAY 10What we ask insteadYour time and your candour. A security or compliance lead in a short weekly session, and honest feedback on where the product is wrong, including the parts you would not buy. That feedback is the return we are after.
DAY 20A small cohort, deliberatelyDesign partners get engineering attention, not a support queue, so cohorts are small and onboarded in sequence. If the current cohort is full we tell you on the call and give you a date, not a waiting-list form.
DAY 30No obligation at day thirtyNothing converts automatically; there is no notice period to serve. Continuing is a separate commercial conversation at day thirty, with the findings already in front of you. Revoke the consent grant in your own tenant and discovery stops the same day.

Fit check

Check the fit before you book

This is a self-qualifier, not a gate. If the first list does not describe you, the pilot will underdeliver, and we would rather you knew that now.

You need all three

01You run a modern identity providerMicrosoft Entra ID or Okta. This is where discovery comes from. Without it the pilot has no day one.
02Your people actually use AICopilot, ChatGPT, Claude, Gemini, an agent somebody built, or a vendor AI feature switched on inside a tool you already licensed.
03You are under framework pressureA regulator, an auditor, or an enterprise customer is asking about AI, and somebody senior has to answer.

Helpful, not required

A CASB or secure web gatewayCloudflare, Netskope, or similar. Widens discovery beyond identity.
An EDR you can queryDefender, CrowdStrike. Adds endpoint context to findings.
An existing model-approval stepEven an informal one. The gate has somewhere natural to attach.

Not sure which regimes reach you? The AI Risk Calculator takes eight questions and no email address.

Book

Bring your security lead. Thirty minutes.

A working session, not a pitch deck. We scope what discovery would actually reach in your environment, which frameworks apply, and whether a design-partner pilot makes sense at all. There is nothing to price: the pilot is free, and the thirty days end with no obligation on either side.

Booking opens our calendar in a new tab; pick any slot. Bring whoever owns your identity tenant. It shortens day one considerably.

Thirty minutes. Three things scoped.
  1. 1What discovery would actually reach in your environment
  2. 2Which frameworks apply
  3. 3Whether a design-partner pilot makes sense at all

Nothing to price. No obligation on either side at day thirty.